One Email, Three Identities: SPF, DKIM and DMARC Explained
This article explains the technical distinction between SPF, DKIM, and DMARC protocols in email authentication. It clarifies that these three mechanisms verify different identities and that a message can pass authentication even if the sender domains do not perfectly align.
Why it matters
Understanding these protocols is critical for IT professionals and developers to prevent email spoofing and ensure legitimate business communications are not flagged as spam.
A single email carries three separate domain identities, plus the IP address it was actually delivered from, and nothing requires any of them to match. Most of the confusion around SPF, DKIM and DMARC comes from assuming there is one "sender" to check. There are three identities, they are checked by different mechanisms, and a message can pass DMARC while two of the three point in different directions.
Here is a constructed example (not a real customer message, but a realistic and common configuration) that shows all of them at once: an invoice email sent through an email service provider (ESP), the way most SaaS billing systems actually send mail.
The mail client shows a customer of acme-example.com an invoice from "Acme Billing". Underneath, these values determine whether that message authenticates:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in